October 5, 2026
There is no single cybersecurity checklist that guarantees a healthcare practice will qualify for cyber insurance. Requirements vary by insurer, policy, practice size, claims history, data exposure, and coverage requested.
However, insurers commonly evaluate controls such as multifactor authentication, endpoint detection and response, secure backups, patching, email security, employee training, privileged access, encryption, monitoring, and incident response planning. Current cyber insurance applications may also ask specifically about PHI, backup frequency, MFA coverage, encryption, prior incidents, and other security practices.
For an independent healthcare practice, these 10 areas provide a practical framework for preparing for cyber insurance underwriting.
Why Do Cyber Insurers Care About Your Security Controls?
Cyber insurance transfers some of the financial risk associated with a cyber event. It does not eliminate the underlying risk.
Before offering coverage, an insurer may evaluate the likelihood that the practice will experience an incident and the potential financial impact if one occurs. Underwriters can consider factors such as the organization's industry, sensitive information, cybersecurity controls, prior incidents and claims, and requested policy terms.
Healthcare practices present an important consideration because they may store or access PHI in addition to financial, employee, and other sensitive information.
For example, Coalition's current cyber insurance application asks whether an organization collects, processes, stores, transmits, or has access to PHI, personally identifiable information, or payment card information. Depending on the applicant, additional questions may address MFA, encryption, backups, and other controls.
The application therefore should not be treated as paperwork that the Practice Administrator or insurance broker completes by guessing.
Your answers need to reflect what is actually implemented.
What 10 Cybersecurity Controls Should a Healthcare Practice Review Before Applying for Cyber Insurance?
1. Multifactor Authentication
Multifactor authentication (MFA) is one of the most important controls to review before applying for cyber insurance.
But simply answering "yes, we use MFA" may not tell the whole story.
Determine where MFA is actually enforced, including:
- Microsoft 365 and business email
- Remote access
- VPN connections
- Administrative accounts
- Cloud applications
- EHR or practice-management systems (where supported)
- Backup administration
- Other systems containing sensitive information
Some insurance applications get this specific. Coalition, for example, separately asks about MFA for email, remote access, and network, cloud, or privileged administrative accounts.
HHS also identifies MFA as one of its Essential Healthcare and Public Health Cybersecurity Performance Goals, where safe and technically capable.
For healthcare practices using Microsoft 365, our 8-step Microsoft 365 security framework provides a broader look at authentication, Conditional Access, account protection, administrative controls, and monitoring.
2. Endpoint Detection and Response
The computers employees use to access email, patient information, cloud applications, and business systems need more than basic maintenance.
Cyber insurers commonly evaluate endpoint protection, including endpoint detection and response (EDR). The Hartford identifies EDR among the core security measures insurers may consider, while Marsh includes EDR among controls associated with cyber resilience and insurability.
EDR can monitor endpoint activity for suspicious behavior and provide capabilities for investigating and responding to potential threats.
For a healthcare practice, coverage should be reviewed across applicable:
- Desktop computers
- Laptops
- Servers
- Remote devices
- Other supported endpoints
The important question is not simply whether EDR software has been purchased.
Ask:
Which devices are protected, who monitors the alerts, and what happens when suspicious activity is detected?
That distinction is one reason cybersecurity needs to be actively managed rather than treated as a collection of security products.
3. Secure and Tested Backups
Ransomware makes backup and recovery particularly important to insurers.
The practice should be able to explain:
- What critical systems and data are backed up
- How frequently backups occur
- Where backup copies are stored
- Whether backups are separated from production systems
- How backup administration is secured
- Whether backups are encrypted where appropriate
- Who monitors backup failures
- How often recovery is tested
Some insurance applications ask very specific questions. Coalition, for example, may ask whether an organization maintains at least weekly backups of sensitive or critical data and systems offline or on a separate network.
Travelers recommends a resilient backup strategy that includes separate copies and protections such as MFA, least-privilege access, and immutable backups where appropriate.
For a more complete healthcare-specific review, see How Should Healthcare Practices Back Up Their Data? A 6-Part Backup Strategy.
4. Patch and Vulnerability Management
Cybercriminals can exploit known vulnerabilities in operating systems, applications, firewalls, network equipment, and other technology.
A practice should therefore know:
- Which systems are being patched
- Who manages patching
- How failed patches are identified
- How critical vulnerabilities are prioritized
- How unsupported systems are handled
- Whether vulnerability scanning is performed
- How identified vulnerabilities are tracked through remediation
The Hartford identifies consistent patching among the security measures insurers may evaluate, while HHS includes mitigating known vulnerabilities among its Essential Cybersecurity Performance Goals for healthcare organizations.
Medical technology may complicate this process because some connected devices have vendor-controlled updates, specialized operating systems, or clinical requirements that affect when changes can be made.
Our 6-step connected medical device security framework addresses those additional considerations.
5. Email Security and Phishing Protection
Email remains a major part of everyday healthcare operations and a common way employees encounter malicious links, attachments, impersonation attempts, and fraudulent requests.
A layered email-security approach may include:
- Anti-phishing protection
- Malicious attachment and link protection
- Spam filtering
- Domain protections
- Impersonation protection
- Appropriate Microsoft 365 configuration
- Employee reporting procedures
- Security awareness training
HHS includes email security among its Essential Cybersecurity Performance Goals for healthcare organizations.
Email security should also work together with MFA.
Filtering attempts to prevent a malicious message from reaching an employee. MFA helps reduce the likelihood that stolen credentials alone can give an attacker access to an account.
Neither should be viewed as a complete solution by itself.
6. Employee Security Awareness Training
Employees are part of the practice's security environment.
Insurers may ask whether employees receive cybersecurity training, and The Hartford specifically identifies employee training among security measures that may affect cyber insurance pricing.
Training should help employees recognize and respond to situations such as:
- Phishing
- Fake login pages
- Suspicious attachments
- Business email compromise
- Password or MFA requests
- Social engineering
- Unexpected payment requests
- Suspicious phone calls
- Improper handling of sensitive information
Employees also need to know how to report something suspicious.
A staff member who recognizes a phishing email but does not know whom to notify cannot help the practice respond quickly.
HHS includes basic cybersecurity training among its Essential Cybersecurity Performance Goals.
7. Identity, Privileged Access, and Employee Offboarding
MFA is only one part of identity security.
A practice should also control who has access to its systems and how much access each person receives.
Review:
- Individual user accounts
- Role-based permissions
- Administrative accounts
- Shared accounts
- Remote access
- Privileged access
- Account creation
- Access changes when roles change
- Prompt removal of access when employees leave
- Periodic access reviews
HHS specifically identifies revoking credentials for departing workforce members, using unique credentials, and separating user and privileged accounts among its Essential Cybersecurity Performance Goals.
Our 7-step healthcare IT access management process provides a practical framework for managing accounts from hiring through termination.
8. Encryption and Protection of Sensitive Data
Healthcare practices should understand where sensitive information exists and how it is protected.
That may include PHI stored or transmitted through:
- EHR systems
- Computers and laptops
- Servers
- Microsoft 365
- Cloud applications
- Backups
- Mobile devices
- Third-party platforms
Cyber insurance applications may specifically ask whether devices are encrypted. Coalition's application, for example, asks about encryption on laptops, desktops, and portable media devices.
HHS also includes strong encryption among its Essential Cybersecurity Performance Goals and continues to recommend appropriate encryption of ePHI in transit and at rest as part of mitigating cyber threats.
The appropriate implementation will depend on where the practice's information is stored and how it is used.
9. Security Monitoring and Incident Response
A practice needs a plan for what happens when security controls detect something suspicious or an incident actually occurs.
That includes knowing:
- Who receives security alerts
- Who investigates them
- Who can isolate a compromised computer
- Who can disable a compromised account
- Who contacts the cyber insurance carrier
- Who coordinates with legal, forensic, and other outside resources
- How leadership is notified
- How the event is documented
- How essential operations continue during the response
An incident response plan should define responsibilities before an incident happens.
Marsh identifies incident response planning among important cyber controls, and Travelers recommends a clearly defined, coordinated approach for responding to cyber incidents.
HHS similarly includes basic incident planning and preparedness among its Essential Cybersecurity Performance Goals.
This also connects directly to business continuity. A ransomware event may be both a security incident and an operational outage.
Our 7-part healthcare business continuity checklist provides a broader framework for keeping essential operations running during a disruption.
10. Security Risk Assessment and Documentation
Finally, the practice should be able to document its security environment accurately.
For HIPAA-regulated healthcare organizations, risk analysis is already an important Security Rule responsibility. HHS continues to emphasize that regulated entities must conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
A useful risk-management process should help the practice document:
- Systems containing or accessing ePHI
- Identified threats and vulnerabilities
- Existing safeguards
- Security gaps
- Remediation priorities
- Responsible parties
- Progress toward remediation
This documentation can also make cyber insurance applications easier to answer accurately.
Our 5-step HIPAA Security Risk Assessment framework explains how practices can approach that process.
How Should a Healthcare Practice Prepare for a Cyber Insurance Application?
Do not wait until the insurance application arrives to start figuring out the answers.
A practical preparation process is:
| Review Area | What the Practice Should Verify |
| MFA | Where it is enforced and where it is not |
| Endpoints | Which devices have EDR or equivalent protection |
| Backups | Frequency, separation, security, monitoring, and testing |
| Patching | How operating systems, applications, and network equipment are maintained |
| Filtering, phishing protection, and account security | |
| Training | Who receives training and how often |
| Access | User, administrator, remote, and former-employee access |
| Encryption | Which sensitive systems and devices are encrypted |
| Incident response | Who responds and how escalation works |
| Risk management | Current risks, remediation, and supporting documentation |
Then involve the appropriate people.
For a small independent practice, that may include the Practice Administrator, insurance broker or agent, IT Service Provider, cybersecurity provider, and other advisors as appropriate.
Marsh's current Cyber Accelerate application guidance specifically recommends having an IT professional available to help answer technical security questions. Its application includes questions about MFA, patching, cybersecurity training, backups, incidents, PHI/PII/PCI, and encryption.
The objective is not to produce the answers the insurer wants to hear.
It is to produce accurate answers that can be supported by the practice's actual technology and security controls.
Why Is Accuracy on a Cyber Insurance Application So Important?
The Practice Administrator may know that the practice "has MFA" or "has backups," but the technical details can matter.
For example, saying the practice uses MFA does not necessarily answer whether MFA protects:
- Remote access
- Administrative accounts
- Cloud applications
- Other critical systems
Likewise, saying the practice has backups does not explain whether they are appropriately separated, protected, monitored, and tested.
That is why the person completing the insurance application should verify technical answers rather than relying on assumptions.
If an application asks a question you do not understand, involve the IT provider and insurance professional before answering it.
Do not interpret an insurance question more broadly than the practice's actual controls support.
Does Meeting Cyber Insurance Requirements Mean the Practice Is Secure?
No, cyber insurance underwriting and cybersecurity risk management have related goals, but they are not the same thing.
An insurer evaluates risk for the purpose of determining whether and under what terms it is willing to provide coverage. A healthcare practice must manage security based on its own systems, data, operations, HIPAA responsibilities, threats, and vulnerabilities.
A control can therefore be important even when a particular insurance application does not ask about it.
HHS's healthcare-specific Cybersecurity Performance Goals illustrate this distinction. Its Essential Goals include not only MFA, email security, and incident preparedness, but also vulnerability mitigation, encryption, workforce credential management, privileged accounts, and vendor cybersecurity requirements.
Cyber insurance should be part of the practice's broader risk-management strategy, not the cybersecurity strategy itself.
Example: Preparing a Small Healthcare Practice for Cyber Insurance Renewal
Consider a hypothetical 18-employee Houston medical practice preparing for its annual cyber insurance renewal.
The Practice Administrator receives a questionnaire asking about MFA, backups, endpoint protection, employee training, encryption, and prior incidents.
Rather than answering from memory, the Administrator reviews the questions with the practice's IT provider.
The review finds that MFA is enforced for Microsoft 365 and remote access, EDR is deployed across managed computers, and employee security training is active. It also identifies two questions that need additional verification: whether a legacy application supports MFA and whether a particular vendor-managed system is included in the practice's documented backup strategy.
Those questions are investigated before the application is submitted.
The value of the review is not simply completing the insurance form.
It gives the practice a clearer picture of which controls are verified and where additional risk-management work may still be needed.
Frequently Asked Questions
Does HIPAA Compliance Automatically Qualify a Healthcare Practice for Cyber Insurance?
No, HIPAA requirements and cyber insurance underwriting are separate. A practice may have HIPAA compliance responsibilities while an insurer asks additional or more specific questions about MFA, EDR, backups, patching, training, encryption, and other cybersecurity controls.
The practice needs to evaluate both its regulatory responsibilities and the underwriting requirements of the particular policy.
Does Having Cyber Insurance Mean We Need Less Cybersecurity?
No, cyber insurance can help transfer certain financial risks, subject to the policy's coverage, exclusions, limits, deductibles, and other terms. It does not prevent a ransomware attack, compromised account, data loss, or operational outage.
Cybersecurity is intended to reduce risk and improve resilience. Insurance addresses certain financial consequences when covered events occur.
Can Better Cybersecurity Lower Our Cyber Insurance Premium?
Potentially, but there is no universal discount for implementing a particular control.
Insurers consider multiple factors when pricing coverage. The Hartford notes that controls such as MFA, regular backups, EDR, patching, and employee training can signal stronger resilience and may help improve pricing.
The practice should implement appropriate security controls because they reduce risk, not solely because they might lower a premium.
What If Our Practice Cannot Meet One of the Insurer's Security Requirements?
Discuss the requirement with the insurance broker or carrier and the practice's IT provider.
The answer may depend on the particular control, system, insurer, and policy. There may be a technical remediation, a compensating control, a different coverage option, or a requirement that must be satisfied before coverage can be offered.
Do not claim that a control exists when it does not.
Should Our IT Provider Complete the Cyber Insurance Application for Us?
The practice should remain responsible for the accuracy of information submitted, but the IT provider can help verify technical answers.
A useful division of responsibility is for the Practice Administrator or appropriate business leader to coordinate the application, the insurance professional to explain coverage and underwriting questions, and the IT provider to verify cybersecurity controls and technical details.
Final Thoughts
Cyber insurance applications have increasingly become a practical test of whether a healthcare practice can explain how its cybersecurity actually works.
The goal should not be to install products solely to check boxes on an insurance form. It should be to maintain appropriate security controls that protect the practice while also allowing underwriting questions to be answered accurately.
If your practice can clearly document MFA, endpoint protection, backups, patching, email security, employee training, access controls, encryption, incident response, and risk management, it will be better prepared for the cyber insurance application process and, more importantly, better prepared to manage cyber risk.
About ResTech Solutions
ResTech Solutions helps independent healthcare practices throughout the Houston area manage technology, cybersecurity, Microsoft 365, user access, backups, security monitoring, and ongoing technology planning.
When a healthcare practice applies for or renews cyber insurance, we can help verify the technical controls that are actually in place so the practice and its insurance professional have accurate information to work from. The insurance broker or carrier remains the appropriate source for coverage, underwriting, and policy questions.
If your practice is preparing for a cyber insurance application or renewal and needs help reviewing its cybersecurity environment, book a 10-minute discovery call and we'll help you identify which technical controls deserve a closer look.

