A few years ago, a cyber insurance application was a short form. Today many insurers ask pages of detailed questions about your security controls, and some require evidence. For healthcare organizations, whose records are valuable to criminals, the underwriting questions can be especially pointed. Answering them poorly can mean higher premiums, narrower coverage or a denied application. Answering them inaccurately can be worse: a claim may be contested if the application misstated your controls.
Here is how to prepare.
Insurers want to know how likely you are to suffer a loss and how large it might be. Controls that reduce the likelihood of ransomware and business email compromise get the closest scrutiny. The questions vary by carrier, but the same themes recur.
Is MFA required for email, remote access and administrator accounts?
Is it required for access to backups?
This is often the single most important question. A no on email or remote access can end the conversation with some carriers.
Are backups taken regularly, and are they stored offline or immutably?
Are they tested, and when was the last restore test?
Are backups separated from the main network credentials?
Do you use endpoint detection and response or a modern managed security tool on workstations and servers?
Who monitors it, and is that monitoring around the clock?
Do you filter email for phishing and malicious attachments?
Do you use protections such as SPF, DKIM and DMARC?
Do staff receive phishing training, and how often?
Do you have a patch process, and how quickly are critical updates applied?
Do you run any unsupported operating systems or applications?
Do you have a written plan, and has it been tested?
Do you have relationships with forensic and legal firms, or will you use the insurer's panel?
Do you limit administrator privileges?
How many records containing PHI do you hold?
Is sensitive data encrypted?
Do you review the security of vendors with access to your systems and data?
Begin the process well before renewal. Gaps such as missing MFA take weeks to fix, and you do not want to find them the week the application is due.
Sit down with your IT provider and answer each question together. Do not guess, and do not let the form be filled out by someone who does not know the environment.
If a control is partial, say so. For example, MFA on email but not on all remote access. Misstatements are a common reason for disputed claims. Have the person who signs the application read every answer.
Save screenshots of MFA policies, backup reports, test results, training logs and policy documents. Insurers increasingly ask for proof, and the same documents support HIPAA compliance.
If you have limited budget, prioritize:
MFA everywhere it is possible.
Offline or immutable backups with a recent restore test.
Modern endpoint protection with monitoring.
Email filtering and staff training.
A written, tested incident response plan.
These are also the controls most likely to reduce actual risk, not just improve your quote.
Ask the broker about:
What the policy covers: forensic costs, legal, notification, credit monitoring, business interruption, ransom, regulatory fines where insurable.
Sublimits and waiting periods.
Exclusions, such as failure to maintain required security controls.
Whether you must use specific vendors for response.
Coverage for incidents at a vendor that holds your data.
Coverage helps pay for recovery, but it does not restore resident trust, undo a care disruption or guarantee a payout. Treat the application as a free checklist of what responsible security looks like.
UnityCare IT works with administrators and brokers to answer technical questions accurately and close the gaps that matter most before renewal. If your next application is coming up, we can review it with you in advance.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172