Cyber liability insurance has changed in recent years. Applications that once fit on one page now often include detailed technical questionnaires, and some carriers decline or surcharge organizations that lack basic controls. For nursing homes, assisted living operators and clinics, which hold sensitive resident data and cannot tolerate long outages, coverage is worth considering. Getting it requires being ready for the questions.
This post describes the topics underwriters commonly raise. Every carrier is different, and policy language matters, so review details with your broker and legal counsel.
This is often the first question. Expect to be asked whether MFA is required for email, remote access, administrator accounts and sometimes for backups and cloud systems. If you answer yes, be sure it is true across the board, not just for part of the staff.
Underwriters want to know:
How often you back up
Whether backups are encrypted
Whether at least one copy is offline, immutable or separated from the main network
How often you test restoring them
If you cannot show a recent restore test, this is a good time to run one.
Many applications ask whether you use endpoint detection and response (EDR) or only traditional antivirus, and whether it is monitored around the clock.
Expect questions about how quickly you apply critical security updates and whether you have unsupported systems still running, such as old operating systems or unpatched servers.
Spam and phishing filtering, attachment and link scanning, and protection against spoofed email domains frequently appear.
Questions typically focus on whether remote desktop is exposed directly to the internet, how VPN access is secured, and whether vendors have always-on remote tools.
Carriers ask how often you train employees and whether you run simulated phishing campaigns.
A written plan with named contacts, tested at least annually, is increasingly expected.
Administrator accounts should be separate from daily accounts, limited in number and protected with MFA.
Because of the nature of your data, expect additional questions on:
Number of resident or patient records you hold
Whether PHI is encrypted on laptops and portable devices
Vendors and business associates with access to PHI
Past HIPAA investigations, breaches or claims
Medical device and connected equipment security
Be accurate. A misstatement on an application can give the carrier grounds to deny a claim or rescind coverage. If a control is partly in place, say so rather than rounding up.
Involve IT early. Do not let the broker or administrator guess. Your IT provider should review technical answers.
Gather evidence. Keep screenshots, reports and logs that show MFA enabled, backup tests, and training records.
Read the exclusions. Look at waiting periods, sublimits for ransomware, requirements to use approved vendors, and what counts as a covered event such as business interruption, forensics, notification costs and regulatory defense.
Understand any conditions. Some policies require you to maintain certain controls throughout the term.
If your answers are weak, prioritize the changes carriers care about most and tend to cost the least:
Enforce MFA on email and remote access
Separate and test backups
Replace or isolate unsupported systems
Close directly exposed remote access
Run regular awareness training
Write and rehearse an incident response plan
These steps help your security regardless of insurance. Insurance is a financial backstop, not a substitute for protection, and it does not restore resident trust or operations after an attack.
What do the sublimits and retentions look like for ransomware?
Does the policy cover regulatory fines and defense costs where permitted?
Are we required to use specific incident responders?
What notice must we give, and how quickly?
Does coverage extend to events at vendors we rely on?
UnityCare IT helps healthcare organizations review insurance questionnaires from a technical perspective, close common gaps and gather the evidence underwriters ask for. If a renewal is coming up, starting a few months early gives you room to fix issues first.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172