Cyber insurance applications have grown more detailed over the last several years. Where an application once asked a handful of yes or no questions, many now ask about multi-factor authentication, backups, endpoint protection, patching and incident response. For healthcare providers, which hold sensitive data and cannot easily stop operating, underwriters pay particular attention.
Preparing in advance can improve your options, reduce surprises at renewal and, more importantly, make your organization safer. This article describes the controls insurers commonly ask about and how to approach the process honestly.
The answers you give are part of your policy. If a claim arises and it turns out a control you said was in place was not, the insurer may dispute coverage. Do not guess and do not rely on assumptions. Have your IT provider verify each answer, and keep supporting documentation. Leadership, not only IT, should sign off.
Expect questions about whether MFA is required for email, remote access, privileged and administrator accounts, and cloud applications. Partial coverage often needs to be described precisely. Saying it is enabled for some users is different from saying it is enforced for all.
Insurers want to know whether backups are performed regularly, stored offline or immutable, kept separate from the main network, encrypted and tested. Be ready to state how often you test restores and when the last test occurred.
Questions often ask about modern endpoint protection with monitoring on all computers and servers, and who responds to alerts.
Expect to describe how quickly critical updates are applied and whether any unsupported operating systems remain in use.
Filtering for phishing and malicious attachments, protections against domain spoofing and warnings on external email may appear.
How are administrator accounts controlled? Do daily-use accounts have admin rights? Are administrative actions logged?
Insurers ask whether staff receive regular security training and simulated phishing exercises, and whether new hires are included.
Have you written and tested an incident response plan? Do you have disaster recovery procedures and downtime plans?
Questions may cover third-party access, remote desktop exposure and how vendors authenticate.
Expect questions about encryption of laptops and databases, data retention and the amount of protected health information you hold.
Before starting the application, collect:
A list of systems and the number of records you hold
MFA coverage reports
Backup logs and most recent restore test
Patch and endpoint protection reports
Your incident response plan and the last time it was reviewed
Training records
Your most recent HIPAA risk analysis
Network diagram and a list of vendors with remote access
Having these ready also shortens the process and avoids answers drawn from memory.
If you find that some controls are missing, address the highest-impact items first. For many organizations, the order is MFA on email and remote access, tested and isolated backups, endpoint protection with active monitoring and a written incident plan. Even partial progress, documented honestly, may improve how your risk is viewed.
Compare coverage carefully:
What is covered: breach response costs, legal fees, notification, business interruption, ransomware, regulatory defense
Sublimits and exclusions
Waiting periods before business interruption coverage starts
Requirements to use approved response vendors
Whether failure to maintain stated controls can void coverage
Retention or deductible amounts
An insurance broker with healthcare experience can help you compare, and your attorney can review language that affects your obligations.
A policy can help pay for recovery, but it does not restore lost trust or protect residents from harm. Treat it as one part of a broader program that includes prevention, detection, response and recovery.
UnityCare IT helps healthcare organizations assemble accurate evidence for insurance applications and close the technical gaps that underwriters ask about. If renewal is coming up, we recommend starting a few months ahead so there is time to act on what you find.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172