Cyber Insurance Applications: What Underwriters Want to See

Cyber liability insurance has changed in recent years. Applications that once fit on one page now often include detailed technical questionnaires, and some carriers decline or surcharge organizations that lack basic controls. For nursing homes, assisted living operators and clinics, which hold sensitive resident data and cannot tolerate long outages, coverage is worth considering. Getting it requires being ready for the questions.

This post describes the topics underwriters commonly raise. Every carrier is different, and policy language matters, so review details with your broker and legal counsel.

The Controls Most Commonly Asked About

Multi-factor authentication

This is often the first question. Expect to be asked whether MFA is required for email, remote access, administrator accounts and sometimes for backups and cloud systems. If you answer yes, be sure it is true across the board, not just for part of the staff.

Backups

Underwriters want to know:

How often you back up

Whether backups are encrypted

Whether at least one copy is offline, immutable or separated from the main network

How often you test restoring them

If you cannot show a recent restore test, this is a good time to run one.

Endpoint protection

Many applications ask whether you use endpoint detection and response (EDR) or only traditional antivirus, and whether it is monitored around the clock.

Patching

Expect questions about how quickly you apply critical security updates and whether you have unsupported systems still running, such as old operating systems or unpatched servers.

Email security

Spam and phishing filtering, attachment and link scanning, and protection against spoofed email domains frequently appear.

Remote access

Questions typically focus on whether remote desktop is exposed directly to the internet, how VPN access is secured, and whether vendors have always-on remote tools.

Security awareness training and phishing tests

Carriers ask how often you train employees and whether you run simulated phishing campaigns.

Incident response plan

A written plan with named contacts, tested at least annually, is increasingly expected.

Privileged access management

Administrator accounts should be separate from daily accounts, limited in number and protected with MFA.

Healthcare-Specific Questions

Because of the nature of your data, expect additional questions on:

Number of resident or patient records you hold

Whether PHI is encrypted on laptops and portable devices

Vendors and business associates with access to PHI

Past HIPAA investigations, breaches or claims

Medical device and connected equipment security

How to Answer Well

Be accurate. A misstatement on an application can give the carrier grounds to deny a claim or rescind coverage. If a control is partly in place, say so rather than rounding up.

Involve IT early. Do not let the broker or administrator guess. Your IT provider should review technical answers.

Gather evidence. Keep screenshots, reports and logs that show MFA enabled, backup tests, and training records.

Read the exclusions. Look at waiting periods, sublimits for ransomware, requirements to use approved vendors, and what counts as a covered event such as business interruption, forensics, notification costs and regulatory defense.

Understand any conditions. Some policies require you to maintain certain controls throughout the term.

Improving Your Position Before Renewal

If your answers are weak, prioritize the changes carriers care about most and tend to cost the least:

Enforce MFA on email and remote access

Separate and test backups

Replace or isolate unsupported systems

Close directly exposed remote access

Run regular awareness training

Write and rehearse an incident response plan

These steps help your security regardless of insurance. Insurance is a financial backstop, not a substitute for protection, and it does not restore resident trust or operations after an attack.

Questions to Ask Your Broker

What do the sublimits and retentions look like for ransomware?

Does the policy cover regulatory fines and defense costs where permitted?

Are we required to use specific incident responders?

What notice must we give, and how quickly?

Does coverage extend to events at vendors we rely on?

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations review insurance questionnaires from a technical perspective, close common gaps and gather the evidence underwriters ask for. If a renewal is coming up, starting a few months early gives you room to fix issues first.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172