A few years ago, a cyber insurance application might have been a single page. Today, many carriers ask detailed questions about security controls before they will offer a quote or renew a policy. For healthcare operators, whose records are valuable and whose downtime is costly, the scrutiny tends to be even higher.
Understanding what underwriters look for helps you answer accurately, qualify for better terms, and improve your security at the same time.
Insurers want to price risk. Organizations with strong basic controls tend to have fewer and less severe incidents, so carriers use the application to separate well-protected organizations from poorly protected ones. Some carriers also run external scans of your internet-facing systems and compare the results with your answers.
Wording varies, but most applications cover similar areas.
Is multi-factor authentication required for email, remote access and administrator accounts?
Is it enforced for all users or only some?
Are privileged accounts separate from everyday accounts?
How quickly are accounts removed when staff leave?
Are backups performed regularly, and are any stored offline or in a way ransomware cannot alter?
When were restores last tested?
Do you have a documented disaster recovery or business continuity plan?
Is modern endpoint detection and response, or at least managed antivirus, installed on all computers and servers?
Are firewalls in place and monitored?
Is remote desktop exposed to the internet?
Are systems patched promptly, and are unsupported operating systems still in use?
Is email filtering in place for phishing and malicious attachments?
Are SPF, DKIM and DMARC configured?
Is security awareness training provided, how often, and does it include phishing simulations?
Do you have a written incident response plan, and have you tested it?
How do you verify wire transfer or payment change requests?
Do you have business associate agreements and review vendor security?
Is sensitive data encrypted at rest and in transit?
How many resident or patient records do you maintain?
It can be tempting to answer yes to everything. Do not. If a claim is filed and the carrier finds that a stated control was not actually in place, such as MFA on all remote access, the insurer may dispute coverage. Be precise: if MFA covers most but not all accounts, say that, and describe the plan to close the gap.
Gather information well ahead of renewal:
Document which security tools are in place and where
Confirm MFA coverage across all systems
Check the date of your last successful restore test
Locate your written policies and incident response plan
Collect proof of training completion
Ask your IT provider to complete the technical sections with you
A short collaboration between the administrator, the finance lead and IT usually produces a better application than any one person alone.
Every no on the form is a recommendation. If you cannot answer yes to multi-factor authentication, tested backups or endpoint protection, those are likely the controls that will most reduce your real risk as well. Prioritize them in your budget.
When comparing policies, ask:
What exactly is covered: ransomware response, business interruption, data restoration, notification costs, regulatory defense, and social engineering or funds transfer fraud?
Are there sublimits or waiting periods?
Which vendors must you use for incident response?
What notice is required, and how soon after discovery?
Are there exclusions for unpatched systems, missing controls or acts of war?
A broker experienced with healthcare can help interpret details.
Insurance helps with costs, but it cannot restore trust with residents and families, or return a week of lost operations. Think of it as one layer in addition to prevention, detection and recovery.
UnityCare IT helps healthcare organizations review the technical sections of cyber insurance applications, verify that controls are actually in place, and close common gaps before renewal. We do not sell insurance, but we can help you give your broker accurate, well-documented answers.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172