Cybersecurity: 24/7/365

A ransomware attack hits your practice on a Tuesday morning. Your EHR is locked. Patient records are inaccessible. The attackers want $500,000. Your staff can't check in patients, process billing, or access lab results. Every hour costs you revenue, and HIPAA requires you to notify every affected patient.
Without cyber insurance, you pay for all of it — the forensic investigation, the legal counsel, the breach notifications, the credit monitoring, the data recovery, the lost revenue, and possibly the ransom. With the right policy, your insurer covers most of those costs and connects you with a response team within hours.
This guide walks you through what cyber insurance covers, what it costs, what insurers require from your practice, and how to avoid the mistakes that leave most small businesses underinsured.
Cyber insurance covers the costs of a data breach or cyberattack: forensic investigation, patient notification, cyber extortion and ransomware response, lost revenue during downtime, data recovery, public relations support, legal defense, and regulatory penalties where insurable. Policies split into two categories: first-party coverage (your direct costs) and third-party coverage (your liability to others).
Incident response and forensics. When a breach happens, your insurer deploys a response team — IT forensics consultants who determine what happened, how the attackers got in, and what data was affected. Without insurance, the full crisis response — forensics, legal counsel, and notification — runs six figures: it averaged $152,000 per incident at smaller companies in the 2025 NetDiligence Cyber Claims Study.
Breach notification. HIPAA requires you to notify every affected individual within 60 days of discovering a breach. That means letters, call centers, and credit monitoring services. IBM's 2025 Cost of a Data Breach Report puts average notification costs alone at nearly $390,000.
Ransomware negotiation and payment. Most policies cover professional ransom negotiation and, where legal, the ransom payment itself. Healthcare cyber claims averaged more than $2 million per incident in 2025 — up from $800,000 in 2024, per Resilience's 2026 healthcare cyber risk report.
Business interruption. Lost revenue during downtime is covered, typically after a waiting period (often 8-12 hours). In the same NetDiligence study, claims that include business interruption cost 650% more than those without — which tells you how expensive downtime really is. If your EHR goes down for two weeks, the lost revenue can exceed the cost of the attack itself.
Data restoration. Recovering or rebuilding corrupted patient data, reconfiguring systems, and verifying data integrity after an incident.
Legal defense. Lawsuits from patients whose data was exposed. Class actions following healthcare breaches are increasingly common.
Regulatory defense and fines. Legal costs for defending against OCR investigations and, where legally insurable, HIPAA fines. HIPAA penalties range from $145 to $2.19 million per violation — regulatory defense coverage is not optional for medical practices.
Settlements. Payments to affected patients from lawsuits or regulatory actions.
Understanding exclusions is just as important as understanding coverage. Six gaps catch practices off guard: unpatched systems, misrepresented controls, social engineering, state-sponsored attacks, prior known incidents, and bodily injury.
If the attack succeeded because you ignored a known vulnerability, your insurer can deny the entire claim. Insurers check. Some carriers scan your network externally before and after incidents.
If your application says MFA is deployed everywhere but it isn't, the insurer can deny your claim for material misrepresentation. In 2024, nearly three times as many US cyber claims closed without payment as with payment, per the NAIC's cyber insurance market report — misrepresentation and inadequate security are common reasons.
Business email compromise (BEC) and wire fraud are among the most common attacks on medical practices. Many policies exclude social engineering unless you add it as an endorsement. Ask for it specifically — a $250,000 sublimit is a reasonable starting point.
Losses from cyberattacks attributed to nation-states may be excluded under "acts of war" clauses. Lloyd's of London mandated these exclusions across its market, and the definition of what counts as state-sponsored is still evolving.
Any breach or vulnerability you knew about before the policy started is excluded.
If a cyberattack causes a medical device failure that harms a patient, your cyber policy probably won't cover the bodily injury claim. That falls to your malpractice insurance.
For a small medical practice with 1-20 providers, expect to pay roughly $1,000 to $3,000 per year for a standalone cyber insurance policy with $1 million per-claim limits. Insureon puts the average for healthcare businesses near $1,000 annually — higher limits, larger practices, and weaker controls push premiums well above that.
Premium factors that affect your rate:
After steep increases from 2021 to 2023 (some practices saw premiums double at renewal), the market softened in 2024-2025. Premiums dropped about 11% on average in 2025, per Lockton's February 2026 market update. But brokers say rates are near the floor — and rising ransomware severity is pressuring them upward.
The recommended coverage level for a medical practice handling PHI is $2 million to $5 million. A typical cyber incident at a small or midsize company costs $264,000 per the NetDiligence claims data, but healthcare breaches run much higher — the average cost of a healthcare data breach reached $7.42 million in 2025. Even a small practice can face six-figure costs from forensics, notification, legal defense, and lost revenue.
If your malpractice insurance includes a cyber "endorsement" or rider, check the limits carefully. Those riders typically cap at $25,000 to $100,000 — that covers almost nothing in a real incident.
Healthcare organizations hold unusually sensitive data, so insurers require seven baseline controls: multi-factor authentication, endpoint detection and response, encrypted and tested backups, prompt patching, documented employee security training, a written incident response plan, and HIPAA compliance. Miss one and you face higher premiums, exclusions, or a declined application.
The days of answering seven questions and getting a quote are over. Cyber insurance applications now read like security audits — 10 or more pages of detailed questions about your infrastructure, policies, and practices. Here is what every major carrier expects:
Every carrier requires MFA on remote access, email, and admin accounts. SMS-based MFA is no longer sufficient — insurers want app-based authenticators or hardware tokens. Insurers enforce this. In Travelers v. ICS (2022), a ransomware claim revealed the insured had MFA on its firewall only — not everywhere it had attested — and the insurer rescinded the $1 million policy entirely. If you haven't deployed MFA yet, start there — it affects both your insurability and your defense against the most common attack vectors.
Traditional antivirus no longer qualifies. Insurers require EDR or managed detection and response (MDR) tools like CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint. These tools monitor for suspicious behavior in real time, not just known malware signatures.
Carriers want to see a 3-2-1 backup strategy: three copies of your data, on two different media types, with one stored offsite (or in the cloud). Backups must be encrypted and tested regularly. "We back up to an external drive" is not sufficient — that drive is often connected to the same network the ransomware encrypts. Proper backup and disaster recovery planning is both an insurance requirement and a business survival strategy.
Insurers ask how quickly you apply security patches, especially critical ones. If a breach traces back to a known, unpatched vulnerability, your claim is at risk. Managed IT providers handle this automatically — break-fix shops typically do not.
Documented security awareness training with phishing simulations is now a standard requirement. "We told everyone to be careful" does not count. Carriers want proof: training platform records, completion certificates, phishing test results.
A written, tested incident response plan that covers who does what during a breach, how you notify patients and regulators, and how you restore operations. Some carriers require proof that you've conducted tabletop exercises.
Applications ask directly: "Is the applicant in compliance with HIPAA?" Practices without a current HIPAA risk assessment may be denied coverage entirely. HIPAA compliance doesn't just keep you out of trouble with OCR — it directly affects your ability to get insured and your premium rate.
Here is what to expect when you apply:
Be honest on the application. If you claim controls are in place when they are not, you risk having every future claim denied. It is better to acknowledge a gap and show a remediation timeline than to misrepresent your security posture.
Every control insurers require — MFA, EDR, tested backups, patching, training, incident response — is built into our healthcare cybersecurity service. We deploy the controls, keep the logs, and produce the documentation carriers ask for at underwriting and renewal.
If you don't have cyber insurance, get it now — before the market turns. If you already have it, review your policy before your next renewal. Here is a quick checklist:
Cyber insurance is not a substitute for security. It is one part of a broader risk management program, and insurance policies work best when you have strong controls underneath them. The practices that pay the lowest premiums and get their claims paid are the ones that take security seriously every day — not just at renewal time.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.