After a wave of ransomware payouts tied to healthcare practices — including incidents that hit hundreds of dental offices at once through shared software vendors — cyber insurance carriers stopped taking practices' word for it. Most now require documented proof of specific controls before issuing or renewing a policy, and they'll deny a claim if those controls weren't actually in place at the time of the breach.
Common requirements include MFA on all systems accessing patient data, encrypted backups tested for recovery, a written and tested incident response plan, documented staff security training, and evidence of regular vulnerability scanning. Some carriers now require an annual penetration test as well.
If you can't produce documentation for these items during the application or renewal process, expect a higher premium, a denied application, or a policy with exclusions that make it far less useful when you actually need it.
The practices that get approved fastest and at the best rates are the ones who walk into the application with their evidence package already assembled — scan reports, training records, the incident response plan, MFA proof — rather than scrambling to produce it under deadline.
This is exactly what our cyber insurance readiness service is built for: getting your documentation and controls in order before you apply or renew, so the process is fast and the coverage actually holds up if you ever need to file a claim.
Get a free 30-minute readiness check — no pressure, just clarity on what you need.
Get My Free Readiness Check