Cyber liability insurance can help cover costs after an incident, such as forensic investigation, legal counsel, notification, business interruption and sometimes ransom-related expenses. For healthcare operators, it is often a prudent part of risk management. But a policy is not a substitute for security, and insurers increasingly expect specific controls to be in place. Misunderstanding the application or the policy language can lead to unpleasant surprises when you file a claim.
This guide gives administrators a list of questions to raise with their broker and their IT team. It is general information, not insurance or legal advice, so work with a qualified broker and counsel.
Does the policy cover first-party costs such as forensics, data restoration, business interruption and extortion payments?
Does it cover third-party liability, such as regulatory defense and fines where legally insurable, and claims from residents or families?
Are breach notification and credit monitoring costs included, and are there limits?
Is there coverage for dependent business interruption, meaning an outage at a vendor you rely on?
Does it cover social engineering or funds transfer fraud, such as a fake invoice or a wire request that looks like it came from your administrator? These are often sub-limited or require a separate endorsement.
What are the aggregate limit and per-claim limits, and are there sub-limits for ransomware or regulatory costs?
What is the deductible or retention?
Does defense spending erode the limit?
What is the waiting period before business interruption coverage begins?
Read these carefully.
Are there exclusions for unpatched software, failure to maintain security controls or unsupported systems?
Is there a war or state-sponsored attack exclusion, and how is it worded?
Are there conditions about multi-factor authentication or backups that could void a claim if not maintained?
Are prior acts covered, and what is the retroactive date?
Is there a 24-hour incident hotline?
Must you use the insurer's panel of forensic firms and attorneys?
When must you notify the carrier? Delays can jeopardize coverage.
Can you get written approval before paying a ransom?
Insurers commonly ask about specific controls on the application. Answer honestly, because material misstatements can jeopardize a claim. Before signing, have IT confirm:
Is multi-factor authentication enforced on email, remote access and administrator accounts?
Are backups encrypted, offline or immutable, and tested?
Do we run endpoint detection and response on all servers and workstations?
How quickly do we patch critical vulnerabilities?
Do we have a documented, tested incident response plan?
Do we provide regular security awareness training and phishing exercises?
Are there any end-of-life systems on our network?
Who has privileged access, and is it reviewed?
If an answer is "mostly," say so and discuss with your broker how to phrase it. It is better to disclose gaps than to check a box that is not accurate.
Insurer questionnaires have become a de facto checklist of baseline security practices. If you cannot answer yes to a control, you have learned where to invest. Improving controls can also improve insurability and, sometimes, pricing.
Put the insurer's hotline and policy number on your one-page incident plan
Know who can authorize engaging outside experts
Keep a copy of the policy where leadership can reach it if systems are down
Include your broker in your tabletop exercises
Insurance does not restore trust with residents and families, repair a damaged reputation or keep care operations running during an outage. It pays for part of the cost afterward. Preventive controls, backups and downtime plans remain your first line of defense, and they are also the controls insurers like to see.
Coverage needs change as you add locations, adopt new systems or handle more data. Review limits and exclusions at each renewal and after any major change.
UnityCare IT helps healthcare organizations answer technical questions on cyber insurance applications accurately and close the control gaps that insurers care about. If a renewal is coming up, we are glad to review the questionnaire with you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172