A few years ago, a cyber insurance application for a small care facility might have been a single page. Today, many applications read like a security audit. Underwriters want to know how you protect backups, who has administrator access, whether you use multi-factor authentication, and how quickly you patch software. For nursing homes, assisted living communities and clinics that hold sensitive resident data, understanding these questions helps with both pricing and eligibility.
This post does not describe any specific insurer's form. Questions vary, but the themes are consistent.
Insurers have paid for many ransomware and business email compromise claims. They have learned which controls tend to separate organizations that recover quickly from those that struggle. Questionnaires are how they screen for those controls. Answers affect whether coverage is offered, the premium, the limits and sometimes the exclusions.
Expect questions about whether MFA is required for email, remote access, administrator accounts, and cloud applications. Many insurers treat missing MFA as a deal-breaker or a reason for higher pricing. Be ready to say exactly where it is enforced, not just where it is available.
Underwriters ask how often you back up, whether copies are stored offline or immutable, whether backups are encrypted, and how recently you tested a restore. A backup that ransomware can reach is not much protection, and insurers know it.
Questions often cover antivirus or endpoint detection and response on servers and workstations, and whether anyone monitors alerts around the clock or during business hours only.
You may be asked how quickly critical updates are applied and whether you run software that vendors no longer support. For example, the end of support for Windows 10 is scheduled for October 14, 2025, so unsupported operating systems will increasingly be a concern.
Filtering for spam and malicious attachments, protection against spoofing, and procedures for verifying wire or payment changes all come up.
Questions cover who has administrator rights, how privileged accounts are managed, and whether you remove access promptly when staff leave.
Insurers ask whether staff receive security awareness training and phishing education, and whether you have a written incident response plan and a plan for business continuity.
You may be asked how you manage third-party risk, including whether you have business associate agreements and whether key vendors carry their own coverage.
This is the most important point. A misstatement on an application, even an honest mistake or an optimistic guess, can give an insurer grounds to dispute or deny a claim later. Do not check yes because a tool is installed on some computers, or because MFA is planned for next month.
A reliable process:
Have your IT provider and leadership review each question together.
Verify answers with evidence, such as screenshots, configuration reports or policy documents.
Where the answer is partial, say so and explain, or ask the broker how to describe it.
Keep a copy of the completed application and supporting evidence.
Update the insurer if material facts change during the policy period, as your policy requires.
Start at least ninety days before the renewal date. Use the time to close gaps, since many are quick wins:
Turn on MFA for email and remote access.
Add an immutable or offline backup copy and test a restore.
Retire or isolate unsupported systems.
Document your incident response plan and contact list.
Run phishing awareness training and keep attendance records.
Ask your broker to walk through coverage for ransom payments, forensic investigation, legal costs, regulatory defense, notification expenses, business interruption and social engineering fraud. Check sublimits, waiting periods and exclusions, including any requirement to use panel vendors. Insurance does not replace security. It transfers part of the financial risk after something goes wrong.
UnityCare IT works with healthcare organizations and their brokers to gather the technical answers underwriters need and close gaps before renewal. If an application is on your desk and you are not sure how to answer a question truthfully, we can help you find out what is actually in place.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034