If you've renewed your practice's cyber liability insurance in the last 12–18 months, you've probably noticed the application got longer. Questions that didn't exist two years ago are now standard — and the answers you give directly affect whether you're covered, how much you pay, and whether a claim gets paid out when you need it most.
This shift isn't accidental. Insurers have absorbed years of healthcare breach data and adjusted accordingly. What used to be a checkbox exercise is now a substantive technical underwriting process — and small practices are increasingly getting caught unprepared.
What Insurers Are Actually Asking
The specific questions vary by carrier, but the themes are consistent. Here's what's appearing on current cyber liability applications for healthcare organizations:
- Do you have multi-factor authentication (MFA) enabled on email and remote access? This is now a near-universal requirement. Practices without MFA on Microsoft 365 or Google Workspace are either being declined coverage or quoted at significantly higher premiums.
- Is your network segmented to separate clinical systems from general traffic? Underwriters want to know whether a compromised front desk workstation can reach your EHR. If the answer is “we don't know” or “everything is on the same network,” that's a red flag.
- Do you have a documented incident response plan? Not a general awareness that breaches are bad — a written plan that identifies who does what in the first 24 hours after a security incident.
- Are your backups stored off-network and tested regularly? The frequency of testing matters. “We back up to an external drive” is no longer an acceptable answer. “We back up nightly to an immutable cloud environment and test restoration quarterly” is.
- Do you have endpoint detection and response (EDR) on your workstations? Basic antivirus is no longer considered adequate. Insurers want active monitoring that can detect and respond to suspicious behavior on individual devices.
What Happens When You Can't Answer These Questions
Practices that can't document their security controls are facing three outcomes:
- Higher premiums. Carriers price risk based on the controls in place. A practice without MFA, network segmentation, and tested backups represents a materially higher risk — and premiums reflect that.
- Coverage exclusions. Some carriers will offer coverage but exclude specific scenarios — ransomware, for example — if the practice can't demonstrate adequate preventive controls. You may think you're covered for the most likely threat you face, and discover at claim time that you're not.
- Claim denial after a breach. This is the worst outcome, and it's happening. If your application stated that you had certain controls in place and the breach investigation reveals you didn't — or if you agreed to maintain controls as a condition of coverage and let them lapse — your carrier has grounds to deny the claim. A breach that cost $200,000 to remediate becomes entirely out-of-pocket.
The Intersection with HIPAA
Cyber liability insurance and HIPAA compliance are increasingly intertwined, and understanding that relationship matters for how you prioritize your security investments.
HIPAA requires a risk analysis — a documented assessment of the threats and vulnerabilities to ePHI in your environment. Cyber liability insurers want evidence of security controls. These two requirements overlap significantly: a thorough HIPAA risk analysis that results in documented controls gives you both the compliance documentation HHS expects and the evidence your insurer wants to see.
Practices that approach these as separate compliance exercises — HIPAA is a legal requirement, insurance is a financial product — miss the efficiency of addressing them together. A single well-documented network security assessment can serve both purposes.
What “Adequate Documentation” Actually Looks Like
Insurers and HIPAA auditors are both asking for evidence, not assertions. “We take security seriously” is not documentation. What they're looking for:
- A network diagram showing how systems are connected and segmented.
- Written security policies that describe how your practice handles access control, device management, and incident response.
- Logs showing that your firewall and systems are being monitored.
- Records of backup tests with documented results.
- A signed Business Associate Agreement with every vendor that touches your systems.
Most small practices don't have any of these on hand. That doesn't mean the work hasn't been done — it means it hasn't been documented in a way that's defensible.
The Practical Starting Point
If your next cyber liability renewal is coming up in the next three to six months, now is the right time to close the gap — not the week before the application is due. Start by requesting your current policy's full list of required controls and representations. Then compare that list against what you can actually document today. The gaps between those two lists are your priority list.
A network assessment from a provider who understands healthcare compliance can identify those gaps, help you close them, and produce the documentation your insurer and HIPAA both want to see — before the application lands in your inbox. Our HIPAA Compliance Program and Managed IT Services keep those controls in place year-round — built exclusively for independent and small group medical practices.
Talk to a healthcare IT partner
Province Technology Solutions helps medical practices across the Twin Cities metro get more from their technology with proactive, predictable IT support. Let's talk about what your practice needs.
Request a Free Consultation