The office manager of a five-provider pediatric group forwarded us her cyber insurance renewal application in May with a note: "This used to be two pages." It was now eleven. It asked whether multifactor authentication was enforced on email, on remote access and on every administrative account. It asked how often backups ran, whether a copy was kept offline or immutable, and when a restore had last been tested. It asked for the endpoint detection product, the patching cadence, whether any Windows Server 2012 machines were still running, and whether staff had completed phishing training in the past year. The signature line said the answers were representations the policy relied on.
She was right to be nervous. Cyber insurance for medical practices changed after the ransomware surge of 2020 to 2022: carriers lost money, premiums rose, and the application turned into a security audit. The good news is that the questions on the form are also the shortest list of controls that actually prevent the incidents a practice is most likely to face. Answer them honestly, fix the ones you answered no to, and the policy gets cheaper and more reliable at the same time.
This article covers what the application asks and why, what a policy pays after an incident and where the sublimits and exclusions sit, a worked example of a ransomware claim at a small practice, and the controls that move the premium.
Key takeaways
- Cyber insurance applications now ask specific yes-or-no questions about multifactor authentication (MFA), endpoint detection and response (EDR), offline or immutable backups, email filtering, patching and training, and a wrong answer can void the policy when you need it.
- A policy typically pays first-party costs (forensics, legal counsel, notification, credit monitoring, data restoration, business interruption, extortion) and third-party costs (privacy liability, regulatory defense and fines where insurable, PCI assessments), each with its own limit.
- Ransomware, social engineering and funds transfer fraud are often sublimited well below the headline policy limit, and business interruption has a waiting period before it pays.
- The six controls that lower premiums are the ones HHS 405(d) and the 2024 Cybersecurity Performance Goals recommend, so the work counts twice.
- The policy does not replace HIPAA obligations: you still owe a risk analysis, breach notification within 60 days of discovery, and the documentation OCR will ask for.
What the application asks, and why
Every carrier's form is different but the questions cluster around a dozen controls, because claims data shows those controls separate a bad week from a bad year. The table lists the common questions, what the carrier is really asking, and what an honest "yes" requires.
| Application question | What the carrier is worried about | What a truthful yes requires |
|---|---|---|
| Is MFA enforced for all email accounts, all remote access and all privileged accounts? | Stolen passwords are the entry point for most business email compromise and many ransomware cases | MFA on Microsoft 365 or Google Workspace for every user, on the VPN or remote desktop gateway, on the EHR if hosted, and on local admin accounts; "most users" is a no |
| Do you use an EDR product on all endpoints and servers? | Traditional antivirus misses the tools attackers use to move laterally | A managed EDR agent on every workstation and server, monitored by someone who responds to alerts after hours |
| Are backups encrypted, kept offline or immutable, and tested? | Attackers delete or encrypt reachable backups before they detonate ransomware | At least one copy that cannot be altered from the network (immutable cloud storage or disconnected media), and a documented restore test in the past year |
| Do you filter inbound email and tag external senders? | Phishing remains the leading initial vector | An email security layer beyond the default, with attachment sandboxing and an external-sender banner |
| Are critical patches applied within a set number of days? Any end-of-life systems? | Unpatched edge devices and old servers are scanned for continuously | A patch cadence you can show in a log, and no unsupported operating systems on the network |
| Do you have a written incident response plan and annual staff training? | Slow, improvised responses cost more | A plan with names and phone numbers, and training records |
The form also asks for pricing context: annual revenue, number of patient records, whether you take card payments, whether the EHR is cloud-hosted or on a server in the closet, which vendors have access to your systems, and any incident or claim in the past three to five years.
Treat every answer as a statement you may have to prove. In 2022 Travelers sued a policyholder in federal court to rescind a cyber policy after a ransomware claim, alleging the application had said MFA was in use when it was not; the case ended with the policy rescinded by agreement. Carriers also scan your public footprint before quoting, so an open remote desktop port or an expired certificate contradicts the form before a human reads it. If the honest answer is no, say no, ask the broker what the premium impact is, and fix it before renewal.
What a claim pays, and what it does not
A cyber policy is really two policies. First-party coverage pays the practice's own costs: the forensics firm that figures out what happened, the privacy attorney (often called a breach coach) who directs the response, notification letters and call center support for affected patients, credit or identity monitoring, restoring data and systems, lost income during downtime (business interruption), and extortion payments if the carrier consents. Third-party coverage pays what you owe others: defense and settlements for privacy lawsuits, regulatory defense and penalties where the law allows them to be insured, and PCI assessments from the card brands after a card data compromise.
Three features decide how much of a loss the policy actually absorbs. The retention (deductible) is what you pay first, commonly in the range of $10,000 to $50,000 for a small practice. Sublimits cap specific coverages below the headline limit; ransomware, social engineering and funds transfer fraud are the usual candidates, and a $1 million policy with a $100,000 social engineering sublimit pays $100,000 when a spoofed vendor email redirects a payment. The waiting period on business interruption, often 8 to 12 hours, means the first shift of downtime is on you, and the income calculation requires records that prove what you would have collected.
Exclusions to read before you sign: acts of war and state-sponsored attacks (wording varies and has been litigated), incidents known before the policy began, failure to maintain the controls represented on the application, unencrypted portable devices, and "betterment," meaning the policy restores what you had but does not buy the upgraded system you should have had. Regulatory fines are covered only where insurable, which differs by state, and not for a violation the carrier considers willful.
A worked example: ransomware at a small practice
Take a fictional eight-employee internal medicine practice with 16,000 active patient records, a cloud EHR, an on-premises file server for scanned documents and a $1 million cyber policy with a $25,000 retention, a $250,000 ransomware sublimit and a 12-hour business interruption waiting period. On a Tuesday morning the file server and every workstation show a ransom note. The EHR is untouched because it is hosted, but the practice cannot see scanned insurance cards, referral letters or its billing exports, and the phone system, which ran on the same network, is down.
The practice calls the carrier's hotline within the hour, which the policy requires. The breach coach engages a forensics firm the same day. Forensics run $45,000 over three weeks. Legal fees are $30,000. Forensics confirm the attacker exfiltrated the scanned document share, so HIPAA notification is required: letters to 16,000 patients, a call center and twelve months of monitoring at about $4 per person, or $64,000, plus notice to HHS and, because more than 500 state residents are affected, the media. Restoration from the immutable backup takes four working days and costs $18,000. The practice sees patients on paper for four days and loses roughly $9,000 a day of net collections it cannot recover, about $36,000 after the waiting period. No ransom is paid because the backups worked.
Total: about $193,000. The practice pays the $25,000 retention; the policy pays the rest, well within limits. Now change one fact: the backups were on a network share the attacker encrypted. The ransom demand is $400,000, the sublimit is $250,000, downtime stretches to three weeks, and the practice is negotiating with criminals while its cash runs out. Same policy, and the difference was one control on the application.
The controls that move the premium
Brokers tell us the same six items decide whether a small practice gets a quote at all and what it pays: MFA everywhere it can be enforced; a managed EDR product with someone watching the alerts; immutable or offline backups with a tested restore; email security beyond the default; no end-of-life systems reachable from the network; and an incident response plan with training records. These are also the core of the HHS 405(d) Health Industry Cybersecurity Practices for small organizations and the Cybersecurity Performance Goals HHS published in January 2024, which means the work you do for the underwriter is the work OCR will ask about after a breach.
Two more items help at renewal: privileged access management (no one works day to day in an admin account) and network segmentation (the phone system and guest wireless are not on the same network as the file server). And keep evidence: screenshots of the MFA policy, the EDR console, the last restore test and the training report. The application is signed once a year; the proof is what you produce when the adjuster asks.
If your EHR or billing vendor holds your data, ask them for their SOC 2 report and confirm their cyber coverage, because your policy will respond to a vendor incident only in part and your patients will still be your patients. Our technology team keeps a plain checklist of these items for the practices we work with, and we review it as part of every RCM audit because downtime is a revenue leak like any other.
Questions we hear
Our IT vendor says we are covered under their policy. Are we?
Almost never in the way you need. A vendor's policy covers the vendor's liability to you, subject to the cap in your contract, and pays nothing toward your notification costs, downtime or regulatory exposure. Ask for the certificate of insurance, read the limitation of liability clause, then buy your own policy.
How much coverage should a small practice carry?
We are not brokers, and it depends on record count, revenue and how much of a response you could fund yourself. Size it by running the worked example above with your own numbers: notification cost per record times records, forensics and legal at realistic rates, and a month of net collections for business interruption. Then compare that figure to the sublimits, not the headline limit.
Does the policy pay the OCR settlement?
Sometimes, in part. Regulatory coverage typically pays defense costs and pays fines and penalties only where the law of the applicable state allows insurance to cover them. It will not pay for the corrective action plan work that follows a settlement, and it will not respond if the carrier finds the violation was willful. Do not buy a policy as a substitute for the security risk analysis.
What to do this week
- Pull last year's application and check every yes against what is actually configured today; list the gaps.
- Confirm MFA is enforced, not merely available, on email, remote access and administrative accounts, and screenshot the policy.
- Locate your backups, confirm one copy is offline or immutable, and schedule a restore test with a written result.
- Read the declarations page for the retention, the ransomware and social engineering sublimits and the business interruption waiting period, and write those numbers into your incident response plan.
- Put the carrier's claim hotline number and the breach coach's name in the plan and on the wall, because the policy requires prompt notice.
- Ask your broker what the premium would be if the open gaps were closed, then decide which to close before renewal.
