Cyber insurance applications used to be a page or two of simple questions. Today they often resemble a security audit. Insurers have paid out large claims for ransomware and data breaches, and they now want evidence that applicants take basic precautions. For healthcare organizations, which hold sensitive data and depend on constant uptime, the questions can be pointed.
Understanding what underwriters want helps you answer accurately, qualify for coverage and, just as importantly, improve your actual protection.
While each insurer differs, these topics appear frequently.
Is MFA required for email, remote access, administrator accounts and, increasingly, for backups and cloud applications? This is often the most important question.
Are backups performed regularly, stored offline or immutable, encrypted and tested? How recently was a restore tested?
Is managed endpoint detection and response installed on workstations and servers? Who monitors alerts, and is monitoring continuous?
How quickly are critical updates applied? Are unsupported operating systems still in use?
Do you filter email for malicious attachments and links? Are there protections against spoofing, such as SPF, DKIM and DMARC records?
Is remote desktop exposed to the internet? Is a VPN or equivalent used with MFA?
Do you have a written plan? When was it last tested? Who is on the response team?
Do employees receive security awareness training, and are phishing simulations conducted?
Do you review third parties that access your data, and do you have contracts that cover security and breach notification?
How are administrator accounts managed and monitored?
Applications are signed statements. If you answer that MFA is enabled everywhere and it covers only email, an insurer may contest a claim later. When a control is partly in place, say so, and describe the scope. Ask your IT provider to review answers before you sign.
If something is not yet implemented, say so and note a plan with a date. Underwriters often prefer an honest answer with a credible plan to an overly rosy one.
Collect documentation such as network diagrams, policies, last backup test results and training records
Confirm MFA status across systems and write down exceptions
Check for end-of-life software and note replacement plans
Run a vulnerability scan on external addresses and fix urgent findings
Review your incident response plan and update contact lists
Start weeks before renewal. Rushing in the last days leaves no time to fix gaps.
Policies vary, so read yours carefully. Many cover costs such as forensic investigation, legal counsel, breach notification, credit monitoring, business interruption and ransom negotiation, subject to terms and exclusions. Look at sublimits, waiting periods, exclusions for unpatched systems or missing controls, and whether you must use the insurer's approved vendors.
Also ask whether the policy covers regulatory defense for HIPAA investigations, and whether it covers incidents at a vendor that holds your data.
Insurance transfers some financial risk. It does not restore trust, recover data, or keep care running. Treat it as one layer alongside the technical and administrative protections you maintain.
Insurers generally consider the strength of your controls, your size, the services you provide and your claims history when deciding whether to offer coverage and at what price. You cannot control the market, but you can control how clearly you present your security posture. A tidy package that includes a short summary of your controls, supporting documents and a remediation plan for known gaps helps your broker advocate for you. Ask your broker whether the insurer offers any security scanning or training resources at no additional charge, since some do.
Even if you are not shopping for coverage, the questions are a handy checklist of widely accepted baseline controls. If you cannot answer yes to most of them, those are worthwhile improvements.
UnityCare IT helps healthcare clients review insurance applications from the technical side, document their controls and close common gaps before renewal. We are not insurance brokers, so please work with your agent on coverage decisions, but we can help make sure your technical answers are accurate.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034