For many senior-living and healthcare operators, cyber insurance renewal has become a project. Applications that once took ten minutes now include pages of technical questions, and insurers may decline coverage or raise premiums when controls are missing. Answering these questions quickly and correctly takes preparation, and it often reveals gaps worth fixing anyway.
This guide covers the questions you are likely to see, why accuracy matters and how to get ready.
Cyber claims can be expensive, and insurers have learned which controls tend to reduce losses. Their questions are a rough picture of what they consider basic hygiene. You do not need to treat them as a punishment. They are a free checklist, and many overlap with HIPAA Security Rule safeguards.
Is multi-factor authentication required for email access?
Is MFA required for remote access, such as VPN or remote desktop?
Is MFA required for administrator and privileged accounts?
Do you use a password manager or enforce password standards?
Do you back up critical data regularly?
Are backups kept offline, offsite or immutable?
Are backups encrypted?
How often do you test restores?
Do you have a written incident response and disaster recovery plan?
Do you use endpoint detection and response or modern antivirus on all computers and servers?
Are systems patched promptly?
Is a firewall in place and managed?
Is the network segmented?
Do you retire unsupported software and operating systems?
Do you filter email for phishing and malware?
Do you have SPF, DKIM and DMARC configured?
Do employees receive security awareness training, and how often?
Do you run phishing simulations?
Do you have written security policies?
Do you perform a risk assessment?
How many records containing personal or health information do you hold?
Do you require security standards of vendors?
Do you use encryption for laptops and portable devices?
Do you verify changes to payment instructions by phone?
Is there dual approval for wire transfers?
It is tempting to answer "yes" to everything. Do not. If a claim occurs and the insurer finds that a stated control, such as MFA, was not actually in place, they may dispute coverage or rescind the policy. Be accurate, and if a control is partially deployed, say so. A good broker can help present partial progress, such as "MFA on email, rollout to remote access in progress with date."
Gather facts before the application arrives. Ask your IT provider for a one-page summary of controls: MFA coverage, backup design, endpoint protection, patching status and training.
Assign one person to own the answers, usually the administrator or compliance officer, with technical review by IT.
Check what is documented. Insurers may ask for evidence such as screenshots, reports or policy copies.
Involve your broker early, ideally several months before renewal.
Turn on MFA for email, remote access and administrators
Verify that backups are isolated and test a restore
Make sure endpoint protection covers every device, not just most
Remove or isolate unsupported systems
Set up email authentication records on your domain
Run short staff training and record attendance
Write a one-page incident response plan with contacts
None of these require large budgets, and each also reduces real risk.
Applications are only half the story. Review the policy for what it actually covers: incident response services, ransomware, business interruption, regulatory defense, notification costs and social engineering fraud. Look for exclusions and conditions, such as required controls or required use of the insurer's approved response vendors. Know the notification procedure and phone number before an incident, and put it on your emergency contact list.
Insurance helps with financial recovery. It does not restore residents' trust, prevent downtime or replace controls. The goal is to be a safer facility and a better risk to insure.
We can prepare a controls summary for your insurance application, help you close gaps before renewal and document your evidence. If your renewal is coming up, reach out early so there is time to fix what the form reveals.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172