Questions Every Administrator Should Ask About Cyber Insurance

Cyber liability insurance can help cover costs after an incident, such as forensic investigation, legal counsel, notification, business interruption and sometimes ransom-related expenses. For healthcare operators, it is often a prudent part of risk management. But a policy is not a substitute for security, and insurers increasingly expect specific controls to be in place. Misunderstanding the application or the policy language can lead to unpleasant surprises when you file a claim.

This guide gives administrators a list of questions to raise with their broker and their IT team. It is general information, not insurance or legal advice, so work with a qualified broker and counsel.

Questions for your broker

What exactly is covered?

Does the policy cover first-party costs such as forensics, data restoration, business interruption and extortion payments?

Does it cover third-party liability, such as regulatory defense and fines where legally insurable, and claims from residents or families?

Are breach notification and credit monitoring costs included, and are there limits?

Is there coverage for dependent business interruption, meaning an outage at a vendor you rely on?

Does it cover social engineering or funds transfer fraud, such as a fake invoice or a wire request that looks like it came from your administrator? These are often sub-limited or require a separate endorsement.

What are the limits and retentions?

What are the aggregate limit and per-claim limits, and are there sub-limits for ransomware or regulatory costs?

What is the deductible or retention?

Does defense spending erode the limit?

What is the waiting period before business interruption coverage begins?

What are the exclusions?

Read these carefully.

Are there exclusions for unpatched software, failure to maintain security controls or unsupported systems?

Is there a war or state-sponsored attack exclusion, and how is it worded?

Are there conditions about multi-factor authentication or backups that could void a claim if not maintained?

Are prior acts covered, and what is the retroactive date?

How do claims work?

Is there a 24-hour incident hotline?

Must you use the insurer's panel of forensic firms and attorneys?

When must you notify the carrier? Delays can jeopardize coverage.

Can you get written approval before paying a ransom?

Questions to confirm with IT

Insurers commonly ask about specific controls on the application. Answer honestly, because material misstatements can jeopardize a claim. Before signing, have IT confirm:

Is multi-factor authentication enforced on email, remote access and administrator accounts?

Are backups encrypted, offline or immutable, and tested?

Do we run endpoint detection and response on all servers and workstations?

How quickly do we patch critical vulnerabilities?

Do we have a documented, tested incident response plan?

Do we provide regular security awareness training and phishing exercises?

Are there any end-of-life systems on our network?

Who has privileged access, and is it reviewed?

If an answer is "mostly," say so and discuss with your broker how to phrase it. It is better to disclose gaps than to check a box that is not accurate.

Use the application as a roadmap

Insurer questionnaires have become a de facto checklist of baseline security practices. If you cannot answer yes to a control, you have learned where to invest. Improving controls can also improve insurability and, sometimes, pricing.

Align insurance with your response plan

Put the insurer's hotline and policy number on your one-page incident plan

Know who can authorize engaging outside experts

Keep a copy of the policy where leadership can reach it if systems are down

Include your broker in your tabletop exercises

Remember what insurance does not do

Insurance does not restore trust with residents and families, repair a damaged reputation or keep care operations running during an outage. It pays for part of the cost afterward. Preventive controls, backups and downtime plans remain your first line of defense, and they are also the controls insurers like to see.

Review annually

Coverage needs change as you add locations, adopt new systems or handle more data. Review limits and exclusions at each renewal and after any major change.

UnityCare IT helps healthcare organizations answer technical questions on cyber insurance applications accurately and close the control gaps that insurers care about. If a renewal is coming up, we are glad to review the questionnaire with you.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172