Ten Questions to Ask Before Buying Cyber Insurance

Cyber insurance has shifted from an optional extra to a standard part of risk management for healthcare organizations. At the same time, applications have grown longer and carriers expect specific security controls. A policy is only useful if it responds when you need it, so it pays to understand what you are buying. Here are ten questions to ask your broker and your carrier, and to discuss internally.

1. What exactly is covered?

Policies are usually built from separate coverages. Ask which are included:

First-party costs: forensic investigation, data restoration, legal counsel, notification and credit monitoring, public relations

Business interruption: lost income during an outage

Extortion: costs related to ransomware demands

Third-party liability: claims from residents, families or others

Regulatory defense: costs of responding to regulators, and sometimes fines where insurable by law

Do not assume that all of these are present, or that limits are equal across them.

2. What are the limits and sublimits?

A headline limit can hide lower sublimits for ransomware, social engineering or regulatory costs. Ask for a table that shows each coverage with its own limit and retention.

3. What is the retention?

The retention, similar to a deductible, is what you pay before coverage begins. Make sure the figure is one your organization could actually fund during an incident.

4. What security controls do we need to have?

Applications commonly ask about multifactor authentication, backups, endpoint protection, patching, email filtering, staff training and an incident response plan. If you answer yes, you need to be able to prove it. Misstating a control on an application can jeopardize a claim, so involve your IT provider when completing it and keep supporting evidence.

5. How is a ransomware claim handled?

Ask about notice requirements, whether you must use the insurer's panel of response firms and how decisions about payments are made. Ask whether there are coinsurance provisions or reduced limits for organizations that lack certain controls.

6. Does the policy cover business interruption and for how long?

For a care facility, revenue loss during downtime can be significant. Ask about the waiting period before interruption coverage begins and how losses are calculated. Also ask whether dependent business interruption applies, meaning an outage at a vendor such as a cloud EHR provider.

7. What are the exclusions?

Read the exclusions section carefully. Common topics include acts of war, failure to maintain security standards, prior known incidents, unencrypted devices and funds transfer fraud. Ask the broker to explain any exclusion that could apply to your operations.

8. Is social engineering and funds transfer fraud covered?

Fraudulent payment instructions, such as a fake email from a vendor asking you to change bank details, are among the most common losses. Coverage is often limited or requires a call-back verification procedure. Ask what is required.

9. Who do we call, and when?

Many policies require immediate notice. Confirm the claims hotline, put it in your incident response plan and print it on paper copies. Ask whether the insurer provides breach counsel and forensics, and whether you can use your own vendors.

10. What do we need to do to renew on good terms?

Carriers reward good security hygiene. Ask what could lower your premium or improve your terms, such as a documented training program, tested backups or an annual tabletop exercise.

Insurance is not a substitute for security

A policy does not restore trust, protect residents or replace the effort of rebuilding systems. It also does not eliminate your HIPAA responsibilities. Think of insurance as the financial backstop, and the security program as your first line of defense. A reasonable approach:

Close the basic gaps first: multifactor authentication, tested offsite backups, patching and staff training.

Document your controls so you can answer applications confidently.

Review coverage annually, since your organization and the threat landscape change.

Where we fit in

UnityCare IT does not sell insurance, but we regularly help healthcare clients prepare for applications by documenting security controls and closing gaps that carriers ask about. If you are renewing soon, we can help you review the questions before you submit them.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172