Cyber insurance has shifted from an optional extra to a standard part of risk management for healthcare organizations. At the same time, applications have grown longer and carriers expect specific security controls. A policy is only useful if it responds when you need it, so it pays to understand what you are buying. Here are ten questions to ask your broker and your carrier, and to discuss internally.
Policies are usually built from separate coverages. Ask which are included:
First-party costs: forensic investigation, data restoration, legal counsel, notification and credit monitoring, public relations
Business interruption: lost income during an outage
Extortion: costs related to ransomware demands
Third-party liability: claims from residents, families or others
Regulatory defense: costs of responding to regulators, and sometimes fines where insurable by law
Do not assume that all of these are present, or that limits are equal across them.
A headline limit can hide lower sublimits for ransomware, social engineering or regulatory costs. Ask for a table that shows each coverage with its own limit and retention.
The retention, similar to a deductible, is what you pay before coverage begins. Make sure the figure is one your organization could actually fund during an incident.
Applications commonly ask about multifactor authentication, backups, endpoint protection, patching, email filtering, staff training and an incident response plan. If you answer yes, you need to be able to prove it. Misstating a control on an application can jeopardize a claim, so involve your IT provider when completing it and keep supporting evidence.
Ask about notice requirements, whether you must use the insurer's panel of response firms and how decisions about payments are made. Ask whether there are coinsurance provisions or reduced limits for organizations that lack certain controls.
For a care facility, revenue loss during downtime can be significant. Ask about the waiting period before interruption coverage begins and how losses are calculated. Also ask whether dependent business interruption applies, meaning an outage at a vendor such as a cloud EHR provider.
Read the exclusions section carefully. Common topics include acts of war, failure to maintain security standards, prior known incidents, unencrypted devices and funds transfer fraud. Ask the broker to explain any exclusion that could apply to your operations.
Fraudulent payment instructions, such as a fake email from a vendor asking you to change bank details, are among the most common losses. Coverage is often limited or requires a call-back verification procedure. Ask what is required.
Many policies require immediate notice. Confirm the claims hotline, put it in your incident response plan and print it on paper copies. Ask whether the insurer provides breach counsel and forensics, and whether you can use your own vendors.
Carriers reward good security hygiene. Ask what could lower your premium or improve your terms, such as a documented training program, tested backups or an annual tabletop exercise.
A policy does not restore trust, protect residents or replace the effort of rebuilding systems. It also does not eliminate your HIPAA responsibilities. Think of insurance as the financial backstop, and the security program as your first line of defense. A reasonable approach:
Close the basic gaps first: multifactor authentication, tested offsite backups, patching and staff training.
Document your controls so you can answer applications confidently.
Review coverage annually, since your organization and the threat landscape change.
UnityCare IT does not sell insurance, but we regularly help healthcare clients prepare for applications by documenting security controls and closing gaps that carriers ask about. If you are renewing soon, we can help you review the questions before you submit them.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172