Skip to main content

For clinics

Cyber hygiene checklist for UK clinics, 2026.

Published 2026-05-25 · 12-item checklist · Approx. 12-minute read

A dental practice, a GP surgery, a vet and a physio clinic look nothing alike from the waiting room. Online, most of them run on the same few systems. There's a website, an online booking system bought from a specialist vendor, an email setup that carries patient correspondence, and a back-office system on the reception PC. That's a small attack surface. It's also the attack surface the ICO writes about when it issues monetary penalty notices to healthcare providers after a data breach.

This is the checklist we'd run if we were starting from scratch on a clinic's public-facing security, in priority order. The first three come first because they deal with the two things that reach patients directly: email that pretends to come from you, and booking details sent without encryption. The other nine tighten things up once those are done. None of the twelve requires buying anything from Vantyris. Our scanner checks the website and email items. Two of the twelve are a conversation and some paperwork, and no scanner can do those for you.

The first three: what reaches your patients

1. Confirm your domain has DMARC enforcing at quarantine or reject

This one stops the scam that uses your clinic's own name. A scammer sends “Your appointment has been rescheduled, click to confirm” to one of your patients from appointments@yourclinic.co.uk. Nothing in your DNS tells the patient's Gmail or Outlook the message is fake, so it lands like any other email from you. DMARC is the DNS record that closes this gap. At p=quarantine, mail that fails the check goes to spam. At p=reject, it isn't delivered at all.

How to verify: ask your DNS provider (your domain registrar, or whoever set up your email) “is DMARC enforcing?” If the answer is “what's DMARC?”, you have your answer. Or paste your domain into mxtoolbox.com/dmarc.aspx for an instant read.

If it isn't: read our DMARC explainer for the exact steps. Whoever maintains your DNS adds one TXT record. About 30 minutes.

2. Confirm your booking system serves HTTPS-only with a valid certificate

If a patient opens your booking page and the address bar says “Not secure”, that's the last thing they see before typing in their details. Under the Data Protection Act 2018, appointment data and contact details are personal data. So is anything a patient types into a free-text symptom box. Sending any of it over an unencrypted connection is a breach waiting to happen.

How to verify: open your booking page in an incognito browser window. The address should start with https:// and the browser shouldn't show a “Not secure” warning. Click the icon to the left of the address to check the certificate hasn't expired. If either check fails, fix it this week.

If it isn't: read how to enable HTTPS. If your booking provider doesn't support HTTPS in 2026, don't wait for them to catch up. Move to one that does.

3. Confirm your domain has SPF, and review who's allowed to send for it

SPF is the DNS record that lists which servers may send email from your domain. DMARC leans on it, along with DKIM. It tends to go wrong slowly. Someone set it up in 2017, every new vendor got added since, and now the record has 14 includes and breaks the 10-lookup limit.

How to verify: mxtoolbox.com/spf.aspx shows the record and the lookup count.

If it isn't: read what is an SPF record. Your DNS administrator adds one TXT record.

The next nine: tightening up

4. Disable TLS 1.0 and 1.1 on the server

Both versions are deprecated, and current browsers already refuse to use them. Leaving them switched on costs you marks on SSL Labs and shows up as a finding in a Vantyris scan. Plain-English explainer. It's about five minutes in your host's SSL panel.

5. Add HSTS (the Strict-Transport-Security header)

One header that tells browsers to use HTTPS for your domain every time. It closes the brief window where someone on hostile Wi-Fi could push a visitor down to plain HTTP. How to enable it safely. Start with a short max-age and raise it over a week.

6. Add a basic Content Security Policy

A Content Security Policy tells the browser which scripts your site is allowed to run, so an injected one gets blocked. That includes the kind that appears when a CMS plugin is compromised. Start basic. You don't need a perfect policy on day one. Plain-English guide. It matters most on WordPress, or on any CMS that runs plugins.

7. Add X-Frame-Options or frame-ancestors

One header, and it blocks clickjacking, where another site loads yours in a hidden frame to trick people into clicking. A clinic site rarely needs to be framed by anyone else, so DENY is usually safe. The anti-clickjacking header. Five minutes.

8. Add a CAA record to your DNS

A CAA record names the certificate authorities allowed to issue TLS certificates for your domain. Any other authority should refuse, which shuts out attacks that rely on tricking one into issuing a certificate in your name. CAA records explained. It's a one-time DNS edit.

9. Set up certificate expiry monitoring

An expired certificate puts a full-page security warning in front of every visitor, which takes the site offline for most people. UptimeRobot's free tier includes a certificate check. Vantyris monitoring emails you 14 days before expiry, at one credit per scheduled scan. Either way, it's the easiest outage on this list to prevent. If your certificate just expired.

10. Ask your booking-system vendor for its security evidence

No scan will find this one. Ask the vendor whether they hold ISO 27001 or Cyber Essentials Plus certification, or have a SOC 2 Type II report. Ask where their servers are hosted and how patient data is encrypted at rest. If they can't answer any of that, your booking system is only as secure as it happened to be on the day they wrote it. Raise it with them, in writing.

11. Set up a regular external scan

Configuration drifts. A plugin update can quietly undo a header you fixed three months ago. Monitoring is there to catch that the same week it happens, instead of at next year's insurance renewal. Vantyris monitoring does this, at one credit per scheduled scan. If you'd rather not pay us, put a quarterly reminder in the calendar and re-run the free teaser.

12. Keep a paper trail in case the ICO asks

The ICO expects you to be able to show how you looked after patient data. It isn't expecting perfection. A folder does the job: your last few scan reports, a note of when you fixed each item, and the date of the next scan. Of the three PDF layouts a Vantyris scan produces, the full report is the one for that folder. It opens with a one-page summary the practice owner can read in a minute, and the footer carries the scan date, scan ID and methodology version.

Where Vantyris fits

We built Vantyris because the existing tools came in two sizes. There are free single-purpose checkers (SSL Labs is excellent, use it for item 4), and there are enterprise platforms priced for companies with a security team. Neither fits a clinic.

The free teaser checks your certificate and security headers, which covers items 2 and 4 to 7, and gives you a partial grade. A verified scan covers items 1 to 8 with the fix for each finding, plus a Cyber Essentials alignment section that maps each finding to the NCSC's five control areas. It costs one credit, and the starter pack is $10€10£10A$15¥1,500AED 40 for five. Monitoring (items 9 and 11) is the optional add-on. If you switch on the public trust page at /trust/your-clinic, its link can go in your item 12 folder or on your insurer's renewal form.

We're not the only way to do any of this. We're a quick way to do most of it in one sitting, for the price of a credit.

Run a free check on your clinic's website now.

No card needed. Create a free account, add your domain, and the teaser gives you a partial grade in seconds. For the full picture with the fixes, a verified scan costs one credit, and five credits cost $10€10£10A$15¥1,500AED 40.

Editorial

Vantyris editorial team · methodology v1.0.0 · references: ICO guidance · NCSC Cyber Essentials